2 * sparse/smatch_type_val.c
4 * Copyright (C) 2013 Oracle.
6 * Licensed under the Open Software License version 1.1
11 * The plan here is to save all the possible values store to a given struct
14 * We will load all the values in to the function_type_val table first then
15 * run a script on that and load all the resulting values into the type_val
18 * So in this file we want to take the union of everything assigned to the
19 * struct member and insert it into the function_type_val at the end.
21 * You would think that we could use smatch_modification_hooks.c or
22 * extra_modification_hook() here to get the information here but in the end we
23 * need to code everything again a third time.
28 #include "smatch_slist.h"
29 #include "smatch_extra.h"
33 struct state_list_stack
*fn_type_val_stack
;
34 struct state_list
*fn_type_val
;
35 struct state_list
*global_type_val
;
38 static int get_vals(void *unused
, int argc
, char **argv
, char **azColName
)
40 db_vals
= alloc_string(argv
[0]);
44 static void match_inline_start(struct expression
*expr
)
46 push_slist(&fn_type_val_stack
, fn_type_val
);
50 static void match_inline_end(struct expression
*expr
)
52 fn_type_val
= pop_slist(&fn_type_val_stack
);
55 int get_db_type_rl(struct expression
*expr
, struct range_list
**rl
)
58 struct range_list
*tmp
;
60 member
= get_member_name(expr
);
66 "select value from type_value where type = '%s'", member
);
70 str_to_rl(&llong_ctype
, db_vals
, &tmp
);
71 tmp
= cast_rl(get_type(expr
), tmp
);
81 * One of the complications is that smatch tries to free a bunch of data at the
82 * end of every function.
84 static struct data_info
*clone_dinfo_perm(struct data_info
*dinfo
)
86 struct data_info
*ret
;
88 ret
= malloc(sizeof(*ret
));
90 ret
->value_ranges
= clone_rl_permanent(dinfo
->value_ranges
);
92 ret
->fuzzy_max
= dinfo
->fuzzy_max
;
96 static struct smatch_state
*clone_estate_perm(struct smatch_state
*state
)
98 struct smatch_state
*ret
;
100 ret
= malloc(sizeof(*ret
));
101 ret
->name
= alloc_string(state
->name
);
102 ret
->data
= clone_dinfo_perm(get_dinfo(state
));
106 static void set_state_slist_perm(struct state_list
**slist
, int owner
, const char *name
,
107 struct symbol
*sym
, struct smatch_state
*state
)
111 sm
= malloc(sizeof(*sm
));
112 memset(sm
, 0, sizeof(*sm
));
118 overwrite_sm_state(slist
, sm
);
121 static void add_type_val(char *member
, struct range_list
*rl
)
123 struct smatch_state
*old
, *add
, *new;
125 member
= alloc_string(member
);
126 old
= get_state_slist(fn_type_val
, my_id
, member
, NULL
);
127 add
= alloc_estate_rl(rl
);
129 new = merge_estates(old
, add
);
132 set_state_slist(&fn_type_val
, my_id
, member
, NULL
, new);
135 static void add_global_type_val(char *member
, struct range_list
*rl
)
137 struct smatch_state
*old
, *add
, *new;
139 member
= alloc_string(member
);
140 old
= get_state_slist(global_type_val
, my_id
, member
, NULL
);
141 add
= alloc_estate_rl(rl
);
143 new = merge_estates(old
, add
);
146 new = clone_estate_perm(new);
147 set_state_slist_perm(&global_type_val
, my_id
, member
, NULL
, new);
150 static void match_assign_value(struct expression
*expr
)
152 char *member
, *right_member
;
153 struct range_list
*rl
;
156 type
= get_type(expr
->left
);
157 if (type
&& type
->type
== SYM_STRUCT
)
160 member
= get_member_name(expr
->left
);
164 /* if we're saying foo->mtu = bar->mtu then that doesn't add information */
165 right_member
= get_member_name(expr
->right
);
166 if (right_member
&& strcmp(right_member
, member
) == 0)
169 if (expr
->op
!= '=') {
170 add_type_val(member
, alloc_whole_rl(get_type(expr
->left
)));
173 get_absolute_rl(expr
->right
, &rl
);
174 rl
= cast_rl(type
, rl
);
175 add_type_val(member
, rl
);
177 free_string(right_member
);
182 * If we too: int *p = &my_struct->member then abandon all hope of tracking
185 static void match_assign_pointer(struct expression
*expr
)
187 struct expression
*right
;
189 struct range_list
*rl
;
192 right
= strip_expr(expr
->right
);
193 if (right
->type
!= EXPR_PREOP
|| right
->op
!= '&')
195 right
= strip_expr(right
->unop
);
197 member
= get_member_name(right
);
200 type
= get_type(right
);
201 rl
= alloc_whole_rl(type
);
202 add_type_val(member
, rl
);
206 static void match_global_assign(struct expression
*expr
)
209 struct range_list
*rl
;
211 member
= get_member_name(expr
->left
);
214 get_absolute_rl(expr
->right
, &rl
);
215 add_global_type_val(member
, rl
);
219 static void unop_expr(struct expression
*expr
)
221 struct range_list
*rl
;
224 if (expr
->op
!= SPECIAL_DECREMENT
&& expr
->op
!= SPECIAL_INCREMENT
)
227 expr
= strip_expr(expr
->unop
);
228 member
= get_member_name(expr
);
231 rl
= alloc_whole_rl(get_type(expr
));
232 add_type_val(member
, rl
);
236 static void asm_expr(struct statement
*stmt
)
238 struct expression
*expr
;
239 struct range_list
*rl
;
243 FOR_EACH_PTR(stmt
->asm_outputs
, expr
) {
245 case 0: /* identifier */
246 case 1: /* constraint */
249 case 2: /* expression */
251 member
= get_member_name(expr
);
254 rl
= alloc_whole_rl(get_type(expr
));
255 add_type_val(member
, rl
);
259 } END_FOR_EACH_PTR(expr
);
262 static void db_param_add(struct expression
*expr
, int param
, char *key
, char *value
)
264 struct expression
*arg
;
266 struct range_list
*rl
;
269 if (strcmp(key
, "*$$") != 0)
272 while (expr
->type
== EXPR_ASSIGNMENT
)
273 expr
= strip_expr(expr
->right
);
274 if (expr
->type
!= EXPR_CALL
)
277 arg
= get_argument_from_call_expr(expr
->args
, param
);
278 arg
= strip_expr(arg
);
281 type
= get_member_type_from_key(arg
, key
);
282 if (arg
->type
!= EXPR_PREOP
|| arg
->op
!= '&')
284 arg
= strip_expr(arg
->unop
);
286 member
= get_member_name(arg
);
289 call_results_to_rl(expr
, type
, value
, &rl
);
290 add_type_val(member
, rl
);
294 static void match_end_func_info(struct symbol
*sym
)
298 FOR_EACH_PTR(fn_type_val
, sm
) {
299 sql_insert_function_type_value(sm
->name
, sm
->state
->name
);
300 } END_FOR_EACH_PTR(sm
);
302 free_slist(&fn_type_val
);
305 static void match_end_file(struct symbol_list
*sym_list
)
309 FOR_EACH_PTR(global_type_val
, sm
) {
310 sql_insert_function_type_value(sm
->name
, sm
->state
->name
);
311 } END_FOR_EACH_PTR(sm
);
314 void register_type_val(int id
)
321 add_hook(&match_assign_value
, ASSIGNMENT_HOOK
);
322 add_hook(&match_assign_pointer
, ASSIGNMENT_HOOK
);
323 add_hook(&unop_expr
, OP_HOOK
);
324 add_hook(&asm_expr
, ASM_HOOK
);
325 select_return_states_hook(ADDED_VALUE
, &db_param_add
);
327 add_hook(&match_inline_start
, INLINE_FN_START
);
328 add_hook(&match_inline_end
, INLINE_FN_END
);
330 add_hook(&match_end_func_info
, END_FUNC_HOOK
);
332 add_hook(&match_global_assign
, GLOBAL_ASSIGNMENT_HOOK
);
333 add_hook(&match_end_file
, END_FILE_HOOK
);